Can UK Crypto Firms Operate While Awaiting FCA Authorization

13 min read
4 views
Sep 30, 2026

UK crypto firms can now file for FCA authorization. Miss the February window and the right to take new customers after October 2027 may shrink. Here is the line that actually matters.

Financial market analysis from 30/09/2026. Market conditions may have changed since publication.

If you run a crypto business in Britain, the question sitting on every founder Slack this week is blunt. Can you keep serving customers while the Financial Conduct Authority decides whether you deserve a licence? The short version is yes, for some firms, under conditions that are easy to miss if you only skim a headline. The longer version is where the real work lives.

What Changed When The Authorization Gateway Opened

Applications opened at seven in the morning UK time on 30 September. That is not a symbolic date. It starts a five month filing stretch for businesses that already operate and want a cleaner path into the new regime. The rules themselves land on 25 October 2027. Between those two points sits a calendar that will sort serious operators from late movers.

I have found that people treat regulator calendars like weather forecasts. They glance, nod, and assume there will be another window. There often is not. Firms that plan to keep offering specified cryptoasset services in the UK are expected to apply by 28 February 2027. File inside that period and, if you qualify, you can keep serving customers while the file is assessed. File late and the safety net looks thinner.

Authorization is not a sticker you peel off an old anti money laundering registration and slap onto a new letterhead. It pulls crypto businesses into standards that cover consumer protection, safeguarding of customer assets, market integrity, and financial resilience. If a firm cannot show it can meet those standards, it will not get permission to provide regulated cryptoasset services in the country. That is the whole point of the shift.

The UK’s new crypto regime will give consumers greater protections and firms a clear framework to operate in. Firms can now apply for authorisation and start preparing for regulation.

– A senior authorization official at the regulator

Why The February Deadline Is Not Cosmetic

The main application period runs through 28 February 2027. Firms that submit during that window may continue providing specified cryptoasset services while the file is reviewed, even if no decision has landed by the day the regime starts. That is the line founders should tape above their monitors.

The regulator expects to determine applications filed in the window before 25 October 2027. Filing is not approval. Each applicant still has to satisfy authorization standards. An incomplete pack does not buy the same seat as a valid application made on time. I have watched too many teams treat a half finished portal form as a ticket. It is not.

Timing becomes ugly when a file is still open on day one of the new rules. An eligible existing business that submitted during the designated period can keep serving customers, including taking on new business, while the application is assessed under the applicable saving provisions. That phrase, saving provisions, is the legal hinge. Miss it and you are arguing from a weaker script.

What Happens If You File After February

A business that waits until after 28 February can still seek authorization. It will not receive the same treatment if the application is still pending when the regime begins. Guidance points to a more limited transitional route for eligible firms in that position. In plain English, you may be able to service contracts that already existed before you entered transition. Taking on new UK business is a different story.

That distinction was discussed in detail before the gateway opened. It is the kind of detail that does not trend on social feeds and then becomes the only detail that matters in a board meeting. Perhaps the most interesting aspect is how ordinary the trap looks. Nobody plans to be late. They plan to polish the org chart one more week.

  • Apply by 28 February 2027 if you want the fuller transitional treatment.
  • Keep serving existing and new customers only if you are eligible and filed in the window.
  • Expect a narrower path if you file later and remain pending on 25 October 2027.
  • Do not treat an incomplete submission as a placeholder that locks your status.

Old Money Laundering Registrations Do Not Travel

Companies already on the register under the Money Laundering Regulations still have to go through the new authorization process. Current registration focuses on financial crime controls. It does not automatically become authorization under the Financial Services and Markets Act framework. That is the sentence compliance teams should print twice.

Existing firms that already hold FSMA permissions may need a variation of permission if they intend to provide crypto activities covered by the new rules. You cannot lean on a general description of yourself as a crypto company and hope the perimeter sorts itself. You have to map the actual services.

Perimeter guidance finalized in September walks through how the regime applies across different business models. The fresh process covers activities that include issuing qualifying stablecoins, operating cryptoasset trading platforms, dealing and arranging transactions, safeguarding cryptoassets, and arranging cryptoasset staking. Mix two of those in one product and you may need more than one permission.

A trading venue that also holds customer assets is the classic example. Stablecoin issuers, custodians, intermediaries, and staking businesses face the same mapping exercise. In my experience, teams that start with a product brochure instead of an activity list waste months. Start with what the customer actually does on the screen.

What The Full Assessment Actually Looks At

Applicants will need more than the controls that got them through anti money laundering registration. Application materials cover business plans, controllers and close links, financial forecasts, governance, IT systems, financial crime controls, compliance monitoring, and complaints procedures. Crypto specific questions then branch according to the permissions you seek.

Customer asset protection sits near the centre for anyone offering custody. The regulator will look at safeguarding, financial resources, and the ability to live inside conduct rules after the stamp is granted. Authorization is not a one day exam. It is a judgment that you can keep meeting the standard once you are live.

UK custody providers are already reshaping products ahead of 2027. Insured Bitcoin custody is one visible move. More than fifty companies sat on the existing cryptoasset register at last count, including large trading venues, infrastructure names, and traditional finance groups that already touch digital assets. Being on that list does not guarantee approval under the incoming system.

The regulator has said it will authorize firms only where they meet minimum standards and where it believes they can keep meeting them after permission is granted. That second half is easy to skip when you are writing a pretty risk section. It is the half that kills files.

TopicWhat changesWhy it matters
MLR registrationDoes not convert into FSMA authorizationExisting status is not a shortcut
Filing windowThrough 28 February 2027 for the fuller pathAffects new business after October 2027
CustodySafeguarding and financial resources under reviewCustomer assets sit at the heart of the test
PermissionsMapped to actual activities, not brand labelsOne product can trigger several permissions

Support Before You Hit Submit

Firms that have not filed can request meetings through the Pre Application Support Service. The idea is simple. Talk through the business model and ask the awkward questions before the portal clock starts. Requests opened in May. Meetings started in July. The sessions are free and available to firms preparing authorization files or variations of existing permissions.

Webinars on the new rules and the authorization pack are available on demand. The regulator has been unusually direct about one habit it does not want. Do not wait until the last week of February and then dump a thin file. Complete applications travel faster than heroic last minute ones. That is not poetry. That is queue math.

September perimeter guidance is part of the same prep stack. It helps a firm decide whether an activity sits inside the new framework before it picks permissions. Get that mapping wrong and you spend the assessment explaining why page three of the business plan does not match page one of the form.

Some overseas businesses are lining up as well. One large global venue has been reported as planning an application as part of a possible return to the UK market. An application is not a relaunch. It is not a promise. It is a file. Until the new system takes effect, firms that already sit under the Money Laundering Regulations must keep meeting those requirements. New MLR applicants after 30 September have been told to contact the pre application service and explain their plans. The two frameworks remain separate processes.

How Consumer Protection Changes The Product Conversation

For years, many crypto products were sold as if speed and novelty were the product. The incoming framework treats disclosures, complaints handling, and the treatment of customers as part of the licence test. That will feel bureaucratic to teams that grew up in a cycle of token launches. It will feel familiar to anyone who has sat through a retail investment authorization.

I do not think that is a tragedy. Markets that want household money eventually look like markets that already hold household money. The cost is real. Policies have to be lived, not laminated. Staff have to know what to do when a customer cannot access an asset and the group chat is on fire. That operational dullness is the price of a clearer framework.

Market integrity rules will also squeeze practices that used to hide in the gap between “not banned” and “not supervised.” Trading platforms, arrangers, and dealers will have to show they can police their own corners. If that sounds abstract, picture a listing process that can no longer shrug when a token’s disclosure pack is theatre.

Safeguarding Is Where Files Get Serious

Custody is the chapter that keeps general counsel awake. Holding customer crypto is not the same as holding a spreadsheet of balances. The assessment will look at how assets are segregated, how keys are controlled, how records would stand up if the firm failed, and whether financial resources match the risk of the book.

Insured custody products are one response. Insurance is not a substitute for controls. It is a layer. Teams that lead with a marketing line about insurance and trail with a vague key management note will find the questions get sharper, not softer. That is as it should be. Customer assets are not a branding exercise.

Financial resilience sits next to safeguarding. Forecasts that only work if token prices rise in a straight line will not impress anyone who has lived through two crypto winters. Build a plan that still makes sense when volumes drop and legal bills do not. Then stress it again.

Governance, Controllers, And The People Question

Authorization files always become people files. Controllers, close links, and the individuals who actually run the shop will be examined. A neat org chart with empty boxes is a tell. So is a founder who is also the compliance officer, the CISO, and the person who answers support tickets at midnight.

That does not mean only giant balance sheets survive. It means roles have to be real. Decision rights have to be written down in a way a supervisor can test. If a close link sits in another jurisdiction with a messy record, expect the conversation to linger there. Hoping nobody notices is not a strategy.

IT systems and operational resilience will get the same treatment. Outages, key person risk, third party hosting, and incident response are no longer side quests. They are part of the permission. Crypto firms that treated infrastructure as a weekend project will feel this more than firms that already run like regulated venues.

Stablecoins, Staking, And The Perimeter Trap

Issuing a qualifying stablecoin is its own regulated activity. Arranging staking is another. Firms that bundled those features into a single app because it looked tidy now have to unbundle them for the form. That is tedious. It is also how you avoid a refusal letter that says you applied for the wrong thing.

Dealing and arranging transactions can sneak into products that marketing still calls a wallet. If your interface helps a customer buy, sell, or find a counterparty, you may be closer to the perimeter than the landing page admits. Read the guidance with a lawyer who is willing to be unpopular in the product meeting.

I’ve found that the cleanest applications start with a one page map. Activity on the left. Permission in the middle. Evidence pack on the right. Everything else is commentary. If the map takes three hours and three arguments, good. Better now than in month four of the assessment.

A Practical Sequence For Teams That Want To Stay Open

  1. Map every customer facing feature to a regulated activity, including the ones product still calls experimental.
  2. Decide whether you need a fresh authorization or a variation of existing permission.
  3. Book pre application support if the model is messy or cross border.
  4. Build the evidence pack around governance, money, systems, crime controls, and complaints, not slogans.
  5. File a complete application before 28 February 2027 if you want the fuller transitional treatment.
  6. Keep MLR obligations alive until the new regime actually starts.

That sequence looks obvious on paper. In a living company it collides with fundraising decks, hiring freezes, and the temptation to wait for one more consultation paper. The consultations that matter for the main rulebook already closed. The main rules and guidance were finalized at the end of June after several rounds. Waiting for a mythical extra chapter is how calendars slip.

What “Continue Operating” Does And Does Not Mean

Continue operating is not a blank cheque. It is a status that depends on eligibility, a valid application in the right window, and the saving provisions that attach to that window. It does not freeze the firm in amber. The regulator can still refuse. It can still ask hard questions. Customers should not be told that an application equals a licence. That would be a new problem on top of the old one.

It also does not mean overseas groups can treat the UK as a soft landing by filing a thin UK wrapper. Controllers, resources, and the actual place where decisions are made will be tested. If the UK entity is a mailbox, the file will look like a mailbox.

On the other side, firms that do the work should get something useful. A clear framework is not romance, but it is a market signal. Banks, payment firms, and asset managers find it easier to work with counterparties that live inside a known perimeter. That is one reason traditional names already appear on the existing register and why more will try the new gateway.

The Human Bit Founders Underestimate

Authorization projects fail in the middle, not at the slogan stage. Someone has to own the evidence pack. Someone has to say no to a product launch that would blow the activity map. Someone has to keep the board from treating the February date as flexible. That person is rarely the person who writes the tweet thread.

Complaints procedures sound boring until a customer loses access during a network incident and a journalist calls. Financial crime controls sound complete until a new flow is added to the app and nobody updates the monitoring rules. These are not theoretical. They are the difference between a file that reads like a living company and a file that reads like a template bought at midnight.

Is the UK trying to be harsh? I do not read it that way. I read a jurisdiction that watched retail losses, custody failures, and market abuse stories elsewhere and decided the amateur hour chapter is over. You can argue about the calibration. You cannot argue that the direction is a mystery.

Questions Boards Should Ask This Month

Which of our products fall inside the new perimeter, and which only look adjacent? Who are the controllers the regulator will actually care about? If the decision is still pending on 25 October 2027, what customer activity are we allowed to keep? If we miss February, what contracts can we service and what new business do we lose?

Those questions sound dry. They are the ones that decide whether a UK desk is still a desk in late 2027. Strategy decks about global expansion look silly next to an unanswered permissions map. Get the map right, then talk about expansion.

One more. Are we telling customers anything that sounds like we are already authorized? If yes, stop. An open application is not a badge. Overclaiming now is a gift to the conduct section of the file.

Where This Leaves The Market

Britain is moving digital asset businesses toward full financial services regulation rather than leaving them in a financial crime alcove. That will shrink the set of firms that can legally offer specified services after October 2027. It should also make the remaining set easier for institutions and households to evaluate. Both effects can be true at once.

Some companies will leave. Some will narrow their product. Some will raise capital they did not want to raise because safeguarding and resilience cost money. Some overseas brands will try to come back through the front door instead of a marketing campaign. None of that is drama. It is what a perimeter does when it finally gets drawn with a thicker pen.

So can UK crypto firms continue operating while they wait? Eligible existing firms that file a valid application by 28 February 2027 can keep serving customers, including new ones, while the assessment runs, even if the decision is still open when the regime starts. Everyone else should read the narrower transitional route twice and plan as if new UK business may stop. That is the honest version. It is less catchy than a yes or no. It is the version that keeps a company in the room.

If you are still polishing the narrative instead of the pack, start the pack. The gateway is open. The calendar is not impressed by brand heat. And the firms that treat this as an operations project rather than a press moment are the ones most likely to still be taking orders when the new rules stop being future tense.

❝
Twenty years from now you will be more disappointed by the things that you didn't do than by the ones you did do. So throw off the bowlines. Sail away from the safe harbor. Catch the trade winds in your sails. Explore. Dream. Discover.
— Mark Twain
Author

Steven Soarez passionately shares his financial expertise to help everyone better understand and master investing. Contact us for collaboration opportunities or sponsored article inquiries.

Related Articles

?>